<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T02:47:53.787082+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-02609</id>
    <title>bdu:2024-02609</title>
    <updated>2026-10-03T02:47:53.873564+00:00</updated>
    <content>bdu:2024-02609</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-02609"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-helm-2024-26147</id>
    <title>BIT-helm-2024-26147 — Helm's Missing YAML Content Leads To Panic</title>
    <updated>2026-10-03T02:47:53.873618+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: helm</p>
<p>Helm is a package manager for Charts for Kubernetes. Versions prior to 3.14.2 contain an uninitialized variable vulnerability when Helm parses index and plugin yaml files missing expected content. When either an `index.yaml` file or a plugins `plugin.yaml` file were missing all metadata a panic would occur in Helm. In the Helm SDK, this is found when using the `LoadIndexFile` or `DownloadIndexFile` functions in the `repo` package or the `LoadDir` function in the `plugin` package. For the Helm client this impacts functions around adding a repository and all Helm functions if a malicious plugin is added as Helm inspects all known plugins on each invocation. This issue has been resolved in Helm v3.14.2. If a malicious plugin has been added which is causing all Helm client commands to panic, the malicious plugin can be manually removed from the filesystem. If using Helm SDK versions prior to 3.14.2, calls to affected functions can use `recover` to catch the panic.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-helm-2024-26147"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0958</id>
    <title>certfr-2024-avi-0958 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T02:47:53.873659+00:00</updated>
    <content>certfr-2024-avi-0958</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0958"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-158615</id>
    <title>EUVD-2026-158615</title>
    <updated>2026-10-03T02:47:53.873678+00:00</updated>
    <content>EUVD-2026-158615</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-158615"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-26147</id>
    <title>fkie_cve-2024-26147</title>
    <updated>2026-10-03T02:47:53.873690+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Helm is a package manager for Charts for Kubernetes. Versions prior to 3.14.2 contain an uninitialized variable vulnerability when Helm parses index and plugin yaml files missing expected content. When either an `index.yaml` file or a plugins `plugin.yaml` file were missing all metadata a panic would occur in Helm. In the Helm SDK, this is found when using the `LoadIndexFile` or `DownloadIndexFile` functions in the `repo` package or the `LoadDir` function in the `plugin` package. For the Helm client this impacts functions around adding a repository and all Helm functions if a malicious plugin is added as Helm inspects all known plugins on each invocation. This issue has been resolved in Helm v3.14.2. If a malicious plugin has been added which is causing all Helm client commands to panic, the malicious plugin can be manually removed from the filesystem. If using Helm SDK versions prior to 3.14.2, calls to affected functions can use `recover` to catch the panic.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-26147"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r53h-jv2g-vpx6</id>
    <title>GHSA-r53h-jv2g-vpx6 — Helm's Missing YAML Content Leads To Panic</title>
    <updated>2026-10-03T02:47:53.873715+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: helm.sh/helm/v3</p>
<p>A Helm contributor discovered uninitialized variable vulnerability when Helm parses index and plugin yaml files missing expected content.</p>
<p>### Impact</p>
<p>When either an `index.yaml` file or a plugins `plugin.yaml` file were missing all metadata a panic would occur in Helm.</p>
<p>In the Helm SDK this is found when using the `LoadIndexFile` or `DownloadIndexFile` functions in the `repo` package or the `LoadDir` function in the `plugin` package. For the Helm client this impacts functions around adding a repository and all Helm functions if a malicious plugin is added as Helm inspects all known plugins on each invocation.</p>
<p>### Patches</p>
<p>This issue has been resolved in Helm v3.14.2.</p>
<p>### Workarounds</p>
<p>If a malicious plugin has been added which is causing all Helm client commands to panic, the malicious plugin can be manually removed from the filesystem.</p>
<p>If using Helm SDK versions prior to 3.14.2, calls to affected functions can use `recover` to catch the panic.</p>
<p>### For more information</p>
<p>Helm's security policy is spelled out in detail in our [SECURITY](https://github.com/helm/community/blob/master/SECURITY.md) document.</p>
<p>### Credits</p>
<p>Disclosed by Jakub Ciolek at AlphaSense.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r53h-jv2g-vpx6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-26147</id>
    <title>gsd-2024-26147</title>
    <updated>2026-10-03T02:47:53.873751+00:00</updated>
    <content>gsd-2024-26147</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-26147"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-26147</id>
    <title>msrc_CVE-2024-26147 — Helm's Missing YAML Content Leads To Panic</title>
    <updated>2026-10-03T02:47:53.873762+00:00</updated>
    <content>msrc_CVE-2024-26147</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-26147"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13708-1</id>
    <title>openSUSE-SU-2024:13708-1 — helm-3.14.2-1.1 on GA media</title>
    <updated>2026-10-03T02:47:53.873778+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>helm-3.14.2-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13708-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:1328</id>
    <title>RHSA-2024:1328 — Red Hat Security Advisory: Red Hat Advanced Cluster Management 2.9.3 security and bug fix container updates</title>
    <updated>2026-10-03T02:47:53.873794+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>opentelemetry: DoS vulnerability in otelhttp opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound cardinality metrics helm: Dependency management path traversal helm: Missing YAML Content Leads To Panic</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:1328"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-ru-2024:4213-1</id>
    <title>SUSE-RU-2024:4213-1 — Recommended update for helm</title>
    <updated>2026-10-03T02:47:53.873820+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Recommended update for helm</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-ru-2024:4213-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-26147</id>
    <title>UBUNTU-CVE-2024-26147</title>
    <updated>2026-10-03T02:47:53.873837+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: helm, Ubuntu:18.04:LTS: helm, Ubuntu:20.04:LTS: helm, Ubuntu:22.04:LTS: helm, Ubuntu:24.04:LTS: helm, Ubuntu:25.10: helm, Ubuntu:26.04:LTS: helm</p>
<p>Helm is a package manager for Charts for Kubernetes. Versions prior to 3.14.2 contain an uninitialized variable vulnerability when Helm parses index and plugin yaml files missing expected content. When either an `index.yaml` file or a plugins `plugin.yaml` file were missing all metadata a panic would occur in Helm. In the Helm SDK, this is found when using the `LoadIndexFile` or `DownloadIndexFile` functions in the `repo` package or the `LoadDir` function in the `plugin` package. For the Helm client this impacts functions around adding a repository and all Helm functions if a malicious plugin is added as Helm inspects all known plugins on each invocation. This issue has been resolved in Helm v3.14.2. If a malicious plugin has been added which is causing all Helm client commands to panic, the malicious plugin can be manually removed from the filesystem. If using Helm SDK versions prior to 3.14.2, calls to affected functions can use `recover` to catch the panic.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-26147"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0641</id>
    <title>WID-SEC-W-2024-0641 — Red Hat Enterprise Linux (Advanced Cluster Management): Mehrere Schwachstellen</title>
    <updated>2026-10-03T02:47:53.873869+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen oder Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0641"/>
  </entry>
</feed>
